20.06.2015 Views

ossim - AlienVault

ossim - AlienVault

ossim - AlienVault

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4.2 Data Flow<br />

To give a better understanding of how each product is integrated, we offer the following step-bystep<br />

description of data flow beginning with the generation of an event:<br />

1. Events are processed by the detectors until an alert is produced in response to<br />

identification of a pattern or anomaly.<br />

2. If necessary, alerts are processed by the consolidators before being sent. The<br />

consolidators send alerts in groups to occupy a minimum of bandwidth.<br />

3. The collector receives alerts using various open communication protocols.<br />

4. The parser normalizes and saves them in the event database.<br />

5. The parser also prioritizes alerts according to the security policy defined in the<br />

framework and information in the systems inventory about the system under attack.<br />

6. The parser assesses the immediate risk represented by the alert and sends an alarm<br />

to the control panel as necessary.<br />

7. Prioritized alerts are sent to each correlation process, which updates their state<br />

variables and eventually sends new alerts with more complete or reliable<br />

information. These alerts are re-sent to the parser to be stored, prioritized, assessed<br />

for risk, etc.<br />

8. The risk monitor periodically displays the state of each risk index as calculated by<br />

CALM.<br />

9. The control panel shows the most recent alarms, updates the state of all the indices<br />

which it compares to their thresholds, and sends out new alarms or performs the<br />

appropriate actions as necessary.<br />

10. From the control panel, the administrator can link and view all events occurring at the<br />

time of the alert using the forensic console.<br />

11. The administrator can also check the concurrent state of the machine involved using<br />

the use, profile, and session monitors.<br />

27

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!